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1 DETAILED ACTION 

2 

3 This action is in response to the communication filed on 10/23/07. 

4 All objections and rejections not set forth below have been withdrawn. 

5 Claims 1 - 17, 20, 22 - 33 are pending. 
6 

7 Continued Examination Under 37 CFR 1. 1 14 

8 

9 A request for continued examination under 37 CFR 1.114, including the fee set 



10 forth in 37 CFR 1 .17(e), was filed in this application after final rejection. Since this 

1 1 application is eligible for continued examination under 37 CFR 1.114, and the fee set 

12 forth in 37 CFR 1 .17(e) has been timely paid, the finality of the previous Office action 

1 3 has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 

14 10/23/07 has been entered. 
15 

16 



1 7 Claim Rejections - 35 USC § 103 

18 

19 The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 

20 obviousness rejections set forth in this Office action: 

21 (a) A patent may not be obtained though the invention is not identically disclosed or described as set 

22 forth in section 102 of this title, if the differences between the subject matter sought to be patented and 

23 the prior art are such that the subject matter as a whole would have been obvious at the time the 

24 invention was made to a person having ordinary skill in the art to which said subject matter pertains. 

25 Patentability shall not be negatived by the manner in which the invention was made. 
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1 

2 Claims 1-10 and 12-33 rejected under 35 U.S.C. 103(a) as being 

3 unpatentable over Bates et al. (Bates), U.S. Patent 6,721,721 B1 in view of 

4 Hericourt et al. (Hericourt), U.S. Patent 7,099,916. 

5 

6 Regarding claim 1 , Bates et al. discloses: 

7 entering a first computer virus status mode in response to a first computer virus 

8 outbreak report indicating a virus attack threat to a computer network (Bates et al. , col. 

9 1 , lines 1 3-52). Bates et al. reports the outbreak of new and more sophisticated viruses, 

10 and in response, the system of Bates et al. is employed for the purpose of protecting 

1 1 against these outbreaks. 

1 2 computing a first computer virus alert time corresponding to entry into the first 

13 computer virus status mode (Bates et al., fig. 7, elem. 214; col. 7, lines 20-35). Herein, 

14 Bates et al. discloses a method for accessing computer content on a local machine or 

15 on a network. Content is filtered based upon a generated virus alert time, a rule derived 

16 from relative time parameters (criterion) entered (via computer means, "computing") by 

17 a user in a virus status mode. The relative time parameters (i.e. "virus found in last 7 

18 days", "not checked in last 14 days") are processed ("computing") into a rule, which is 

19 then utilized by the system to compare with the timestamps of content and make 

20 determinations of trustworthiness (Bates et al., col. 1 1 , lines 12-24; col. 13, lines 22-34; 

21 col. 17, lines 35-49; col. 18, lines 22-30). 
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1 , comparing a time stamp of a executable computer code with the first computer 

2 virus alert time (Bates et al., col. 9, line 65 - col. 10, line 3; col. 11, lines 12-24; col. 12, 

3 lines 59-62); 

4 and determining the executability of the computer content in response to the 

5 result of the comparing step (Bates et al., col. 9, line 56 - col. 10, line 8; col. 11, lines 

6 12-24). Bates et al. discloses that in response to a comparison, a determination of 

7 computer content executability is performed. 

8 Bates discloses that a time stamp of the executable code corresponds, inter alia, 

9 to the time the code was virus scanned. However, Bates does not explicitly disclose 

10 that a time stamp of the executable computer code corresponds to an execution time of 

1 1 the computer code. 

12 Hericourt teaches that virus scanning of executable code comprises an execution 

13 of the code, and therefore "an earliest moment" the code is allowed to execute (3:25- 

14 54). 

15 It would have been obvious to one of ordinary skill in the art to recognize 



16 teachings of Hericourt within the system of Bates. This would have been obvious 

17 because one of ordinary skill in the art would have been motivated by the general 

18 teachings of Bates for virus scanning and the teachings of Hericourt for the effective 

1 9 accomplishment of such. 

20 Furthermore, the combination enables for execution "on a computer coupled to 

21 the computer network" (Bates, fig. 1). 
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1 Regarding claim 2, the combination enables: 

2 receiving a first access control time based on the first virus outbreak report 

3 (Bates et al., fig. 7, elem. 214). The system of Bates et al. takes human input and 

4 "automatically" generates computer readable parameters. 

5 and converting the first access control time into the first virus alert time (Bates et 



6 al., fig. 7, elem. 214; col. 12, lines 59-62). A "prior point in time" ("virus alert time") is 

7 derived from the period of time specified by element 214 ("access control time") and is 

8 compared to the timestamp of the file. 
9 

10 Regarding claim 3, the combination enables: 

1 1 wherein the first access control time is a relative time stamp (Bates et al., fig. 7, 

12 elem. 214; col. 12, lines 59-62). A "prior point in time" ("virus alert time") is derived from 

1 3 the period of time specified by element 214 ("access control time") and is relative in 

14 time. 
15 



16 Regarding claim 4, the combination enables: 

1 7 wherein the first access control time is a predetermined time period for access 

1 8 control under the first computer virus status mode (Bates et al., fig. 7, elem. 214). The 

19 access control time is pre-determined by the user. 
20 

21 Regarding claim 5, the combination enables: 
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1 determining the presence of a value representing the computer content in a 

2 memory table of executable computer content (Bates et al., col. 7, lines 1 2-34). 
3 

4 Regarding claim 6, the combination enables: 

5 wherein the computer content is not executed when the value representing the 



6 computer content is not present in the memory table of executable computer content 

7 (Bates et al., col. 1 1 , lines 1 1-24; col. 3, lines 24-27). As disclosed by Bates et al., 

8 content not present in the memory table of executable computer content is flagged as 

9 untrustworthy. The invention as disclosed by Bates et al. is configurable to eliminate 

1 0 untrustworthy computer content from the list of accessible content, thus not providing 

1 1 access to the content for execution. 
12 



13 Regarding claim 7, the combination enables: 

14 wherein the value is a hash value of the computer content (Bates et al., col. 12, 

15 lines 55-58). 
16 

17 Regarding claim 8, the combination enables: 

1 8 wherein the computer content is determined to be executable only when the 

1 9 computer content is time stamped prior to the first computer virus alert time (Bates et 

20 al., col. 13, lines 42-59; col. 3, lines 24-27). Computer content that is time stamped 

21 prior to the first computer virus alert time is branded as trustworthy. Thus, the content 

22 would not be subjected to denial of access for execution. 
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1 

2 Regarding claim 9, the combination enables: 

3 entering types of computer codes that should be blocked from execution in 

4 response to the first computer virus outbreak report (Bates et al., col. 9, line 62 - col. 

5 10, line 28); 

6 and blocking execution of a computer code that belongs to the entered types of 



7 computer codes (Bates et al., col. 3, lines 24-27). The invention as disclosed by the 

8 combination is configurable to eliminate untrustworthy computer content from the list of 

9 accessible content, thus not providing access to the content for execution. 
10 

1 1 Regarding claim 10, the combination enables: 

12 generating a second virus alert time in response to a second computer virus 

1 3 outbreak report; comparing the time stamp of the computer content with the second 

1 4 computer virus alert time; determining the executability of the computer content in 

1 5 response to the result of comparing the time stamp of the computer content with the 

16 second computer virus alert time (Bates etal., col. 3, lines 5 -15). The above 

17 limitations of claim 10 are essentially similar to claim 1 with the exception that they are 

1 8 directed to a second instance of the method of claim 1 . The combination enables for 

19 the method of claim 1 produces a set of results. Thus, the combination enables a 

20 secondary instance of the method of claim 1 , as a the word "set" dictates more than a 

21 singular occurrence of the method of claim 1 . 
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1 performing antivirus processing upon the computer content (Bates et al., col. 9, 

2 lines 62-66). The combination enables the processing of computer content for the 

3 likelihood of existing viruses. 
4 

5 Regarding claim 12, it is rejected, at least, for the same reasons as claim 1, and 

6 furthermore because the combination enables: 

7 an access control console, for entering a first computer virus status mode in 

8 response to receiving a computer virus outbreak report indicating a virus attack threat to 

9 a computer network and for recovering a preselected virus access control time 

10 corresponding to said virus status mode (Bates et al., fig. 1 , elem. 33; fig. 7); 

1 1 an antivirus module, coupled to the access control console, configured to 



12 compute a virus alert time based on the virus access control time and to compare a time 

1 3 stamp of target computer code corresponding to an earliest moment the computer code 

1 4 was allowed to execute with the virus alert time prior to execution of the target computer 

15 content (Bates et al., fig. 1 , elem. 30; see rejections of claims 1 and 2). 

16 and wherein the anti-virus module is further configured to determine the 

1 7 executability of the computer content in response to comparing the time stamp of the 

18 target computer content with the virus alert time (Bates et al., col. 9, line 56 - col. 10, 

19 line 8; col. 11, lines 12-24). The combination enables for in response to a comparison, 

20 a determination of computer content executability is performed. Thus the combination 

21 enables content executability determination, comprising an anti-virus module, used to 

22 determine the trustworthiness ("executability") of content. 
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1 

2 Regarding claim 13, the combination enables: 

3 a memory module for storing time stamps of the plurality of computer contents 

4 (Bates et al., fig. 1 , elem. 46); 

5 and an access control module, coupled to the access control console and to the 



6 memory module, for computing the virus alert time and for comparing the time stamp of 

7 each target computer content with the virus alert time (Bates et al., fig. 1 , elem. 42; see 

8 rejections of claims 1 and 2). 
9 



10 Regarding claim 14, the combination enables: 

11 a computer virus processing module, coupled to the access control module, for 

1 2 further processing a target computer content in order to determine the executability of 

1 3 toe target computer content (Bates et al., fig. 1 , elem. 44). 
14 

15 Regarding claim 15, the combination enables: 

1 6 wherein the memory module stores a value representing each of the computer 

17 contents (Bates et al., col. 12, lines 52-65). 
18 

19 Regarding claim 16, the combination enables: 

20 wherein the access control module is configured to determine the presence of 

21 the value in the memory module as representing a target computer content (Bates et al., 

22 fig. 3). 
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1 

2 Regarding claim 17, the combination enables: 

3 wherein the value is a hash value (Bates et al., col. 12, lines 52-65). 
4 

5 Regarding claim 20, it is rejected, at least, for the same reasons as claim 1, and 

6 furthermore because the combination enables: 

7 creating a list of time-stamped executable computer contents (Bates et al., fig. 3, 

8 elem. 92). 

9 entering a virus alert mode in response to a virus outbreak report indicating a 

10 virus attack threat to a computer network (Bates et al., fig. 2; col. 1, lines 13-52). 

1 1 responsive to the virus alert mode, entering an access control message for 



1 2 specifying an access control rule for blocking the execution of suspicious or susceptible 

1 3 computer contents that have a time stamp corresponding to an earliest moment the 

14 computer file was allowed to execute, and the time-stamp is not before a computed 

1 5 virus alert time, the access control message including a first control parameter for 

16 computing the virus alert time (Bates et al., fig. 2; fig. 7; see rejections of claims 1 and 

17 2). 



1 8 receiving a request to execute a target computer content; and determining the 

1 9 executability of the target computer content based on the access control rule in the 

20 access control message (Bates et al., fig. 2). 
21 

22 Regarding claim 22, the combination enables: 
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1 receiving the access control message; automatically converting the first control 

2 parameter into the virus alert time; comparing the time stamp of the target computer 

3 content in the list with the virus alert time; and determining the executability of the target 

4 computer content based on the result of the comparing step (Bates et al., fig. 2, fig. 3, 

5 fig. 7; see rejections of claims 1 and 2). 
6 



7 Regarding claim 23, the combination enables: 

8 applying an anti-virus operation upon the target computer content (Bates et al., 

9 fig- 3). 
10 

1 1 Regarding claim 24, the combination enables: 

12 a second control parameter for specifying types of computer contents that should 

13 be subject to the access control rule (Bates et al., col. 9, line 62 - col. 10, line 28); 

14 a third control parameter for specifying an expiration time for the access control 

15 rule (Bates et al., fig. 7, elem. 217); 

1 6 and a fourth control parameter for identifying the access control message (Bates 

17 et al., fig. 2). 
18 

19 Regarding claim 25, the combination enables: 

20 determining validity of the access control message based on the third control 

21 parameter (Bates et al., fig. 3); 
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1 



Regarding claim 26, the combination enables: 



2 



determining executability of the target computer content based on the second 



3 



control parameter (Bates et al., col. 9, line 62 - col. 10, line 28); 



4 



5 



Regarding claims 27 and 28, they are rejected for the same reasons as claims 20 



6 and 22, and further because the combination enables the usage of their system in a 

7 network of communicating computers (Bates et al., fig. 1). Communications to a user 

8 can be blocked when computer content is deemed to be untrustworthy (Bates et al., col. 

9 3, lines 24-27, col. 14, line 6 - col. 15, line 8). 
10 

1 1 Regarding claim 29, the combination enables: 

12 wherein the data communication is blocked when the target computer content is 

1 3 time-stamped not before the virus alert time (Bates et al., fig. 3; fig 7). 
14 

1 5 Regarding claim 30, it is rejected, at least, for the same reasons as claim 1 , and 

16 furthermore because the combination enables: 

17 a firewall module monitoring data communications initiated by a target computer 

1 8 content and sending a request to examine the data communications (Bates et al. , fig. 1 , 

19 elems.20, 30, 50). The combination enables that the system is useful in a network and 

20 it is capable of filtering trustworthy and untrustworthy computer content - thus, acting as 

21 a firewall module. 
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1 an access control console, for generating an access control message specifying 

2 an access control rule for blocking data communications of the target executable 

3 computer file that has a time stamp corresponding to an earliest moment the computer 

4 file was allowed to execute, and the time-stamp is not before a virus alert time, the 

5 access control message including a first control parameter for computing the virus alert 

6 time in response to a virus outbreak report indicating a virus attack threat to a computer 

7 network (Bates et al., fig. 7; fig. 2); 

8 and an access control module, coupled to the access control console and the 

9 firewall module, configured to receive the access control message and a request from 

1 0 the firewall module, and to compute the virus alert time based on the virus access 

1 1 control time and to determine whether the data communication should be blocked 

12 based on the access control rule (Bates et al., fig. 1 , elem. 44, see rejections of claims 1 

13 and 2). 
14 

15 Regarding claim 31, it is a program and computer medium claim implementing 

16 the method claim 1 , and it is rejected for the same reasons (see also, Bates et al., fig. 

17 1). 
18 

19 Regarding claim 32, it is rejected, at least, for the same reasons as claim 1, and 

20 furthermore because the combination enables: 
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1 means for entering a computer virus status mode in response to a virus outbreak 

2 report indicating a virus attack threat to a computer network and for automatically 

3 recovering a preselected virus access control time (Bates et al M fig. 7); 

4 coupled to the entering and recovering means, means for computing a virus alert 

5 time based on the virus access control time (Bates et al., fig. 1 , elems. 31 , 42, 44), 

6 and coupled to the computing virus alert time means, means for comparing a 

7 time stamp of a target computer content with the virus alert time prior to execution of the 

8 computer content (Bates et al., fig. 1 , elem. 42), 

9 and for determining the executability of the computer content in response to 



1 0 comparing the time stamp of the target computer content with the virus alert time (Bates 

11 et al., col. 9, line 56 -col. 10, line 8; col. 11, lines 12-24). The combination enables a 

1 2 determination of computer content executability is performed for determining the 

13 trustworthiness ("executability") of content. 
14 



15 Regarding claim 33, it is rejected, at least, for the same reasons as claim 1, and 

16 furthermore because The combination enables: 

1 7 means for storing time-stamped executable computer contents (Bates et al., fig. 

18 1, elem. 46); 

1 9 a firewall means for monitoring data communications occurring to the executable 

20 computer contents (Bates et al., fig. 1, elems. 44, 29, 52). 
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1 means for entering a computer virus status mode in response to a virus outbreak 

2 report indicating a virus attack threat to a computer network and for automatically 

3 recovering a preselected virus access control time (Bates et al., fig. 7); 

4 coupled to the entering and recovering means, means for computing a virus alert 

5 time based on the virus access control time (Bates et al., fig. 1, elems. 31, 42, 44). 

6 and coupled to the computing virus alert time means, the storing means, and the 



7 firewall means, means for comparing a time stamp of an executable computer content 

8 with the virus alert time to determine whether the data communication occurring to the 

9 executable computer content should be blocked (Bates et al., fig. 1 , elem. 44, 42). 
10 

11 



12 Claim 11 is rejected under 35 U.S.C. 103(a) as being unpatentable over the 

1 3 combination of Bates et al. and Hericourt in view of Symantec, "Norton Antivirus 

14 Corporate Edition". 

15 

16 Regarding claim 1 1 , The combination enables that viruses can be found in email 



17 attachments, and that it is well known in the art for antivirus programs to have the 

18 capability for performing antivirus processing on emails and email attachments (Bates et 

19 al., col. 1, lines 35-63). The combination enables an antivirus program or module for 

20 performing such antivirus processing (Bates et al., fig. 1, elems. 44, 52). Bates et al., 

21 however, does not disclose the details of the antivirus processing for emails and email 

22 attachments. Specifically, Bates et al. does not disclose that the antivirus program or 
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1 module removes the computer content from the E-mail body, and denies execution of 

2 the computer content. 

3 Symantec discloses an antivirus program and the details of how the program 

4 performs antivirus processing upon an email with an attachment. Symantec discloses 

5 that the antivirus program scans content attached to an email body and removes such 

6 content if it is found to contain a virus, thus, denying execution of the content 

7 (Symantec, page 15, par. 2; page 22, "Managing Realtime Protection"). 

8 It would have been obvious for one of ordinary skill in the art to combine the 

9 details disclosed by Symantec for the antivirus processing of emails with the system of 

10 Bates et al. because the system of The combination enables an antivirus program 

1 1 capable of performing antivirus processing for processing of emails. 
12 

13 



1 4 Response to Arguments 

15 

16 Applicant's arguments filed 10/23/07 have been fully considered but they are not 

17 persuasive. 
18 

1 9 Applicants argues or assert essentially that: 

20 

21 (i) Neither Bates nor Hericourt discloses or suggests using a time stamp that 

22 corresponds to an earliest moment the computer code was allowed to execute on a 

23 computer coupled to a computer network. Thus, even if Bates discloses a time stamp 
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1 indicating when code was virus scanned, and the scanning comprised an execution as 

2 allegedly taught by Hericourt, there is no teaching or suggestion that the time stamp 

3 corresponds to an earliest time that the code was scanned or executed. Both references 

4 assume that code is scanned multiple times, and neither reference attaches any special 

5 significance to an earliest time that the code was scanned (or executed). Rather, the 

6 time stamp in the references might well be the latest time the code was scanned or 

7 executed. (Remarks, pg. 14) 
8 

9 In response the examiner respectfully notes the applicant's admission that prior 

1 0 art assumes that code is scanned multiple times. The examiner furthermore adds that 

1 1 prior art assumes that code, is not only scanned and executed multiple times, but that 

12 code (i.e. computer games, etc., Bates, fig. 8:242) is executed a multitude of times by a 

1 3 multitude of users for purposes other than virus scanning (Bates, 1 :34-63). It would be 

14 illogical to conclude that program developers develop programs and that program users 

15 request and acquire developed programs solely for the exercise of scanning the 

16 programs for viruses. 

17 Thus, in view of the applicant's own admission and common sense as possessed 

18 by those of ordinary skill in the art, the examiner respectfully finds as unpersuasive the 

19 applicant's assertion that the combination of Bates and Hericourt neither discloses or 

20 suggests using a time stamp that corresponds to an earliest moment the computer code 

21 was allowed to execute on a computer coupled to a computer network. The examiner 

22 first notes that the combination of Bates and Hericourt enables for the execution of 
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1 computer code on computers coupled to a network (Bates, fig. 1). Second, the 

2 examiner respectfully notes that out of the multitude of instances a particular piece of 

3 computer code is executed, either via scanning or via end-user execution, the 

4 timestamp associated with the virus check for that computer code represents "an 

5 earliest execution time" in comparison to subsequent instances of execution for that 

6 piece of computer code. 
7 



8 Conclusion 

9 

10 The prior art made of record and not relied upon is considered pertinent to 

11 applicant's disclosure. 
12 

1 3 See Notice of References Cited. 

14 

1 5 A shortened statutory period for reply is set to expire 3 months (not less than 90 

16 days) from the mailing date of this communication. 

17 Any inquiry concerning this communication or earlier communications from the 

18 examiner should be directed to Jeffery Williams whose telephone number is (571) 272- 

19 7965. The examiner can normally be reached on 8:30-5:00. 

20 If attempts to reach the examiner by telephone are unsuccessful, the examiner's 

21 supervisor, Emmanuel Moise can be reached on (571) 272-3865. The fax phone 
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1 number for the organization where this application or proceeding is assigned is (703) 

2 872-9306. 



4 Patent Application Information Retrieval (PAIR) system. Status information for 

5 published applications may be obtained from either Private PAIR or Public PAIR. 

6 Status information for unpublished applications is available through Private PAIR only. 

7 For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 

8 you have questions on access to the Private PAIR system, contact the Electronic 

9 Business Center (EBC) at 866-217-9197 (toll-free). 
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